blob: d98baefc4c7eef6a5f39039948064a4a95d64120 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * ebt_mark_m
3 *
4 * Authors:
5 * Bart De Schuymer <bdschuym@pandora.be>
6 *
7 * July, 2002
8 *
9 */
Jan Engelhardt18219d32008-10-08 11:35:13 +020010#include <linux/module.h>
11#include <linux/netfilter/x_tables.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070012#include <linux/netfilter_bridge/ebtables.h>
13#include <linux/netfilter_bridge/ebt_mark_m.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070014
Jan Engelhardt2d06d4a2008-10-08 11:35:15 +020015static bool
Jan Engelhardt62fc8052009-07-07 20:42:08 +020016ebt_mark_mt(const struct sk_buff *skb, struct xt_action_param *par)
Linus Torvalds1da177e2005-04-16 15:20:36 -070017{
Jan Engelhardtf7108a22008-10-08 11:35:18 +020018 const struct ebt_mark_m_info *info = par->matchinfo;
Linus Torvalds1da177e2005-04-16 15:20:36 -070019
20 if (info->bitmask & EBT_MARK_OR)
Jan Engelhardt8cc784e2008-10-08 11:35:13 +020021 return !!(skb->mark & info->mask) ^ info->invert;
22 return ((skb->mark & info->mask) == info->mark) ^ info->invert;
Linus Torvalds1da177e2005-04-16 15:20:36 -070023}
24
Jan Engelhardtb0f38452010-03-19 17:16:42 +010025static int ebt_mark_mt_check(const struct xt_mtchk_param *par)
Linus Torvalds1da177e2005-04-16 15:20:36 -070026{
Jan Engelhardt9b4fce72008-10-08 11:35:18 +020027 const struct ebt_mark_m_info *info = par->matchinfo;
Linus Torvalds1da177e2005-04-16 15:20:36 -070028
Linus Torvalds1da177e2005-04-16 15:20:36 -070029 if (info->bitmask & ~EBT_MARK_MASK)
Jan Engelhardtbd414ee2010-03-23 16:35:56 +010030 return -EINVAL;
Linus Torvalds1da177e2005-04-16 15:20:36 -070031 if ((info->bitmask & EBT_MARK_OR) && (info->bitmask & EBT_MARK_AND))
Jan Engelhardtbd414ee2010-03-23 16:35:56 +010032 return -EINVAL;
Linus Torvalds1da177e2005-04-16 15:20:36 -070033 if (!info->bitmask)
Jan Engelhardtbd414ee2010-03-23 16:35:56 +010034 return -EINVAL;
35 return 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -070036}
37
Florian Westphal6e705f52010-01-27 14:39:05 +010038
39#ifdef CONFIG_COMPAT
40struct compat_ebt_mark_m_info {
41 compat_ulong_t mark, mask;
42 uint8_t invert, bitmask;
43};
44
45static void mark_mt_compat_from_user(void *dst, const void *src)
46{
47 const struct compat_ebt_mark_m_info *user = src;
48 struct ebt_mark_m_info *kern = dst;
49
50 kern->mark = user->mark;
51 kern->mask = user->mask;
52 kern->invert = user->invert;
53 kern->bitmask = user->bitmask;
54}
55
56static int mark_mt_compat_to_user(void __user *dst, const void *src)
57{
58 struct compat_ebt_mark_m_info __user *user = dst;
59 const struct ebt_mark_m_info *kern = src;
60
61 if (put_user(kern->mark, &user->mark) ||
62 put_user(kern->mask, &user->mask) ||
63 put_user(kern->invert, &user->invert) ||
64 put_user(kern->bitmask, &user->bitmask))
65 return -EFAULT;
66 return 0;
67}
68#endif
69
Jan Engelhardt043ef462008-10-08 11:35:15 +020070static struct xt_match ebt_mark_mt_reg __read_mostly = {
71 .name = "mark_m",
Jan Engelhardt001a18d2008-10-08 11:35:14 +020072 .revision = 0,
73 .family = NFPROTO_BRIDGE,
Jan Engelhardt2d06d4a2008-10-08 11:35:15 +020074 .match = ebt_mark_mt,
75 .checkentry = ebt_mark_mt_check,
Florian Westphalfc0e3df2010-02-15 18:16:26 +010076 .matchsize = sizeof(struct ebt_mark_m_info),
Florian Westphal6e705f52010-01-27 14:39:05 +010077#ifdef CONFIG_COMPAT
78 .compatsize = sizeof(struct compat_ebt_mark_m_info),
79 .compat_from_user = mark_mt_compat_from_user,
80 .compat_to_user = mark_mt_compat_to_user,
81#endif
Linus Torvalds1da177e2005-04-16 15:20:36 -070082 .me = THIS_MODULE,
83};
84
Andrew Morton65b4b4e2006-03-28 16:37:06 -080085static int __init ebt_mark_m_init(void)
Linus Torvalds1da177e2005-04-16 15:20:36 -070086{
Jan Engelhardt043ef462008-10-08 11:35:15 +020087 return xt_register_match(&ebt_mark_mt_reg);
Linus Torvalds1da177e2005-04-16 15:20:36 -070088}
89
Andrew Morton65b4b4e2006-03-28 16:37:06 -080090static void __exit ebt_mark_m_fini(void)
Linus Torvalds1da177e2005-04-16 15:20:36 -070091{
Jan Engelhardt043ef462008-10-08 11:35:15 +020092 xt_unregister_match(&ebt_mark_mt_reg);
Linus Torvalds1da177e2005-04-16 15:20:36 -070093}
94
Andrew Morton65b4b4e2006-03-28 16:37:06 -080095module_init(ebt_mark_m_init);
96module_exit(ebt_mark_m_fini);
Jan Engelhardtf776c4c2008-01-31 04:00:30 -080097MODULE_DESCRIPTION("Ebtables: Packet mark match");
Linus Torvalds1da177e2005-04-16 15:20:36 -070098MODULE_LICENSE("GPL");